CVE-2026-29143
- EPSS 0.25%
- Veröffentlicht 02.04.2026 08:49:31
- Zuletzt bearbeitet 16.04.2026 18:58:05
SEPPmail Secure Email Gateway before version 15.0.3 does not properly authenticate the inner message of S/MIME-encrypted MIME entities, allowing an attacker to control trusted headers.
CVE-2026-29138
- EPSS 0.22%
- Veröffentlicht 02.04.2026 08:47:49
- Zuletzt bearbeitet 16.04.2026 19:01:10
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to claim another user's PGP signature as their own.
CVE-2026-29131
- EPSS 0.23%
- Veröffentlicht 02.04.2026 08:46:15
- Zuletzt bearbeitet 16.04.2026 19:07:50
SEPPmail Secure Email Gateway before version 15.0.3 allows attackers with a specially crafted email address to read the contents of emails encrypted for other users.
CVE-2026-29142
- EPSS 0.13%
- Veröffentlicht 02.04.2026 08:44:51
- Zuletzt bearbeitet 16.04.2026 19:00:35
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to forge a GINA-encrypted email.
CVE-2026-29137
- EPSS 0.19%
- Veröffentlicht 02.04.2026 08:42:38
- Zuletzt bearbeitet 16.04.2026 19:01:40
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to hide security tags from users by crafting a long subject.
CVE-2026-29141
- EPSS 0.21%
- Veröffentlicht 02.04.2026 08:34:32
- Zuletzt bearbeitet 16.04.2026 19:00:20
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to bypass subject sanitization and forge tags such as [signed OK].
CVE-2026-29135
- EPSS 0.25%
- Veröffentlicht 02.04.2026 08:31:52
- Zuletzt bearbeitet 16.04.2026 19:03:04
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to craft a password-tag that bypasses subject sanitization.
CVE-2026-29134
- EPSS 0.23%
- Veröffentlicht 02.04.2026 08:29:20
- Zuletzt bearbeitet 16.04.2026 19:03:15
SEPPmail Secure Email Gateway before version 15.0.3 allows an external user to modify GINA webdomain metadata and bypass per-domain restrictions.
CVE-2026-29140
- EPSS 0.12%
- Veröffentlicht 02.04.2026 08:27:52
- Zuletzt bearbeitet 16.04.2026 19:00:32
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to cause attacker-controlled certificates to be used for future encryption to a victim by adding the certificates to S/MIME signatures.
CVE-2026-29133
- EPSS 0.23%
- Veröffentlicht 02.04.2026 08:26:26
- Zuletzt bearbeitet 16.04.2026 19:06:51
SEPPmail Secure Email Gateway before version 15.0.3 allows an attacker to upload PGP keys with UIDs that do not match their email address.